Apache HTTP Server is a powerful and flexible HTTP/1.1 compliant web server.
Security Fix(es):
A carefully crafted request uri-path can cause modproxyuwsgi to read above the allocated memory and crash (DoS). This issue affects Apache HTTP Server versions 2.4.30 to 2.4.48 (inclusive).(CVE-2021-36160)
Malformed requests may cause the server to dereference a NULL pointer. This issue affects Apache HTTP Server 2.4.48 and earlier.(CVE-2021-34798)
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.(CVE-2021-40438)
{ "severity": "Critical" }
{ "src": [ "httpd-2.4.43-9.oe1.src.rpm" ], "x86_64": [ "httpd-debugsource-2.4.43-9.oe1.x86_64.rpm", "httpd-devel-2.4.43-9.oe1.x86_64.rpm", "httpd-debuginfo-2.4.43-9.oe1.x86_64.rpm", "mod_session-2.4.43-9.oe1.x86_64.rpm", "httpd-2.4.43-9.oe1.x86_64.rpm", "mod_proxy_html-2.4.43-9.oe1.x86_64.rpm", "httpd-tools-2.4.43-9.oe1.x86_64.rpm", "mod_ssl-2.4.43-9.oe1.x86_64.rpm", "mod_ldap-2.4.43-9.oe1.x86_64.rpm", "mod_md-2.4.43-9.oe1.x86_64.rpm" ], "aarch64": [ "mod_ssl-2.4.43-9.oe1.aarch64.rpm", "mod_md-2.4.43-9.oe1.aarch64.rpm", "httpd-devel-2.4.43-9.oe1.aarch64.rpm", "httpd-tools-2.4.43-9.oe1.aarch64.rpm", "httpd-debuginfo-2.4.43-9.oe1.aarch64.rpm", "mod_ldap-2.4.43-9.oe1.aarch64.rpm", "mod_proxy_html-2.4.43-9.oe1.aarch64.rpm", "httpd-debugsource-2.4.43-9.oe1.aarch64.rpm", "httpd-2.4.43-9.oe1.aarch64.rpm", "mod_session-2.4.43-9.oe1.aarch64.rpm" ], "noarch": [ "httpd-help-2.4.43-9.oe1.noarch.rpm", "httpd-filesystem-2.4.43-9.oe1.noarch.rpm" ] }
{ "src": [ "httpd-2.4.43-9.oe1.src.rpm" ], "x86_64": [ "mod_session-2.4.43-9.oe1.x86_64.rpm", "httpd-debuginfo-2.4.43-9.oe1.x86_64.rpm", "httpd-2.4.43-9.oe1.x86_64.rpm", "httpd-tools-2.4.43-9.oe1.x86_64.rpm", "httpd-debugsource-2.4.43-9.oe1.x86_64.rpm", "mod_ssl-2.4.43-9.oe1.x86_64.rpm", "mod_ldap-2.4.43-9.oe1.x86_64.rpm", "mod_proxy_html-2.4.43-9.oe1.x86_64.rpm", "mod_md-2.4.43-9.oe1.x86_64.rpm", "httpd-devel-2.4.43-9.oe1.x86_64.rpm" ], "aarch64": [ "httpd-debuginfo-2.4.43-9.oe1.aarch64.rpm", "httpd-tools-2.4.43-9.oe1.aarch64.rpm", "mod_md-2.4.43-9.oe1.aarch64.rpm", "mod_ssl-2.4.43-9.oe1.aarch64.rpm", "httpd-debugsource-2.4.43-9.oe1.aarch64.rpm", "httpd-2.4.43-9.oe1.aarch64.rpm", "mod_ldap-2.4.43-9.oe1.aarch64.rpm", "mod_session-2.4.43-9.oe1.aarch64.rpm", "httpd-devel-2.4.43-9.oe1.aarch64.rpm", "mod_proxy_html-2.4.43-9.oe1.aarch64.rpm" ], "noarch": [ "httpd-help-2.4.43-9.oe1.noarch.rpm", "httpd-filesystem-2.4.43-9.oe1.noarch.rpm" ] }